
ããã«ã¡ã¯ãHabrïŒ Huawei Blogãé£çµ¡ãåããŸããïŒ
ããšã³ãžãã¢ã®ããã®ãã³ããã®æ¬¡ã®å·ã¯æŸéäžã§ãã
ãããŠä»æ¥ãç§ãã¡ã®ã²ã¹ãã¯åèªç§°å·ãCisco 2960S-24-PWRã¢ãã«ã®é©åãªä»£æ¿åãã®ææè ã§ããããäŸ¡æ Œ/æ§èœãæ¯ã®Huaweiã©ã€ã³ã®ãªãŒããŒã§ããHuawei S5720-52X-PWR-SI V2R9SPC500ã¹ã€ããã§ãã

ç§ãã¡ã®ããŒããŒã«é¢ããçãé¢ä¿æžé¡ïŒ
48GE PoE +ã4 * 10GEããŒãã
SIããŒãžã§ã³ã¯ãRIPãOSPFãªã©ã®L3ã«ãŒãã£ã³ã°ããµããŒãããŠããŸãã
ãœãããŠã§ã¢ããŒãžã§ã³V200R009C00SPC500ã
é»æº500WãPoEã§å©çšå¯èœãª370ã
1 / 10GEã¢ãããªã³ã¯ãä»ããŠã¹ã¿ããã³ã°ãå¯èœã§ãã
10GEã€ã³ã¿ãŒãã§ã€ã¹ã¯ãSNRãå«ãã»ãŒãã¹ãŠã®ãã©ã³ã·ãŒããŒããµããŒãããŸãã
Webã€ã³ã¿ãŒãã§ã€ã¹ãšCLIïŒtelnetãssh v2ïŒãSNMP v2c / v3ãeSightãä»ããéäžç®¡çããµããŒããããŠããŸãã
ãŸããæ¬æ¥ã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãšIPé»è©±ãæ¥ç¶ããããã®ã¢ã¯ã»ã¹ã¹ã€ãããšããŠS5720ã䜿çšããçµéšã«çŠç¹ãåœãŠãŸãã
æåã«ãç¹å®ã®åé·æ§ãèšå®ããŸããã ãã®ã¿ã¹ã¯ã«ã¯ãS5700-LIã¹ã€ããã®å®äŸ¡ãªã©ã€ã³ã§ååã§ãããå°æ¥ã®äœ¿çšãèæ ®ããŠããã®ã¢ãã«ãæ¡çšãããæ£åœåãããŸãã-ãã¹ãã®çµãããŸã§ã«ãäºæ³å€ã®ã«ãŒãã£ã³ã°ãå¿ èŠã§ããã
ãããããã€ã³ãã«ç§»ããŸããã-S5720ã«ã€ããŠäœãç¥ããå®éã«æ€èšŒããŸãããïŒ
æåã®çµéšã VLAN
ãªãã£ã¹ãããã¯ãŒã¯ããã³é»è©±çšã«äœæãããVLANã æ§æããããã©ã³ã¯ãšãŠãŒã¶ãŒããŒãã LLDPãæå¹ã«ãªããŸããã
é³å£°VLANã®æäœã§ã¯ãããŒãã¯ããã€ããªãããã¢ãŒãã§æ§æãããŸãã Yealink IP Phoneã«ã¯ãLLDPèšå®ãååŸããæ©èœããããããã䜿çšããŸããã
æ§æåŸããŠãŒã¶ãŒãã©ãã£ãã¯ã¯ãªãã£ã¹ãããã¯ãŒã¯ã«æ®ããé³å£°ãã©ãã£ãã¯ã¯é³å£°VLANã«ç§»åããŸããã åæã«ãé»è©±ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã®è¿œå ã®æ§æã¯äžèŠã§ããã移è¡äžã«éåžžã«äŸ¿å©ã§ãã
LLDPãæå¹ã«ãããšãæ¥ç¶ãããããã€ã¹ã®èŠä»¶ã«åŸã£ãŠPoEãå²ãåœãŠãããšãã§ããã¹ã€ããã®é»åããžã§ãããçµæžçã«æ¶è²»ããŸãã
ã«ãŒãã£ã³ã°ãèšå®ãããšãã«è³ªåã¯ãããŸããã§ãã-ãã¹ãŠãåäœããŸãã åºæ¬çãªã«ãŒãã£ã³ã°èšå®ïŒ
router id 192.168.30.4
#
ospf 1
area 0.0.0.0
network 10.0.50.0 0.0.0.255
#
interface Vlanif50
mtu 9198
ospf timer hello 1
ospf timer dead 3
ãã¢èªèšŒã¯æ€èšŒãããŠããŸããã åæãå éããããã«ãéæšæºã®ã¿ã€ãã³ã°ïŒãããããLANããŒã¹ã®èšèšãïŒãæ§æãããŸããã ASA5512ã¯ãé£æ¥ããšããŠæ£åžžã«äœ¿çšãããŸã-åäœããŸãã
ãã¥ã¢ã³ã¹ããªãããã§ã¯ãããŸãããSIã·ãªãŒãºãåçã«ãŒãã£ã³ã°ããµããŒãããŠãããšããäºå®ã«ãããããããVlanïŒVlanifïŒã€ã³ã¿ãŒãã§ã€ã¹éã§ã®ã¿å¯èœã§ãã ããªãã¡ ããŒããL3ã¢ãŒãã«ããŠIPã¢ãã¬ã¹ãå²ãåœãŠãããšã¯ã§ããŸããã ããã¯ãEIãHIã·ãªãŒãºã§ã®ã¿å¯èœã§ãã

2çªç®ã®çµéšã å®å šæ§
æãäžè¬çãªã¿ã€ãã®è åšã«å¯Ÿããä¿è·ãšããŠãDHCPã¹ããŒãã³ã°ãIPãœãŒã¹ã¬ãŒããARPã»ãã¥ãªãã£ãèšå®ããŸããããããã¹ãŠãçµã¿åãããããšã§ãæå³ããªããã®ãå«ãããªãã£ã¹ãããã¯ãŒã¯ã§æãäžè¬çãªããã€ãã®ã¿ã€ãã®æ»æãåé¿ã§ããŸãã
管çè ã«ãšã£ãŠããããã¯ãŒã¯äžã®éæ³ãªDHCPãµãŒããŒã®åºçŸãé çã®çš®ã«ãªãããšã¯åšç¥ã®äºå®ã§ãã DHCPã¹ããŒãã³ã°ã¯ããã®åé¡ã解決ããããã«èšèšãããŠããŸãã ãã®å Žåã®ã¢ãã¬ã¹ã®é åžã¯ãä¿¡é Œã§ããããŒãããã®ã¿å¯èœã§ãããä»ã®ããŒãã§ã¯ãããã¯ãããŸãã
DHCPã¹ããŒãã³ã°ã«åºã¥ããŠãIPãœãŒã¹ã¬ãŒãããã³ARPã»ãã¥ãªãã£æ©èœã¯ãIPããã³MACã¢ãã¬ã¹ã®åœé ããä¿è·ããŸãã ããã§äžçªäžã®è¡ã¯ãDHCPã«ãã£ãŠååŸãããã¢ãã¬ã¹ã§ã®ã¿äœæ¥ãå¯èœã§ããããport â IP â MACãã®æãèªåçã«äœæããããã§ãã¯ããããšããããšã§ãã
ãã®èšå®ã¯ã誰ããä»ã®èª°ãã®IP-MACã䜿çšãããå ŽåããŸãã¯MITMæ»æïŒãäžéè ãïŒã®ãããªæ»æãçµç¹ãããå Žåã«åœ¹ç«ã¡ãŸãã
èãããã3çªç®ã®è åšã¯STPæ»æã§ãã ããã§ã¯ããŠãŒã¶ãŒããŒãã®ä¿è·ãšããŠBPDUãã£ã«ã¿ãªã³ã°ãæå¹ã«ãªã£ãŠããŸãïŒã€ãŸããSTPãã¬ãŒã ã¯ãŠãŒã¶ãŒãšã®éã§éåä¿¡ãããŸããïŒã
ããã«ãå€éšã®BPDU stp bpdu-protectionã®åºçŸãç£èŠãããŸããããã¯ãå¥ã®ã¹ã€ããã«æ¥ç¶ãããšãããŸãã¯stpã«ãŒããæ»æãããšãã«å¯èœã§ãã
ã¢ã¯ãã£ãåããããªãã·ã§ã³ãstp edge-port enableãã¯ãSTPèšç®ããããŒããé€å€ããåææéãšã¹ã€ããã®è² è·ã軜æžããŸãã
stp bpdu-protectionãšstp edge-port enableã®çµã¿åããã¯ãã·ã¹ã³ã®ã¹ããã³ã°ããªãŒportfastã«äŒŒãŠããŸãã
å®éã«ã¯ãæ§æäŸïŒ
dhcp enable
#
dhcp snooping enable
dhcp snooping alarm dhcp-rate enable
dhcp snooping user-bind autosave flash:/dhcp-bind.tbl write-delay 6000
arp dhcp-snooping-detect enable
dhcp server detect
vlan 2
name office
dhcp snooping enable
dhcp snooping check dhcp-request enable
dhcp snooping check dhcp-rate enable
arp anti-attack check user-bind enable
ip source check user-bind enable
vlan 3
name guest
dhcp snooping enable
dhcp snooping check dhcp-request enable
dhcp snooping check dhcp-rate enable
arp anti-attack check user-bind enable
ip source check user-bind enable
vlan 4
name voice
dhcp snooping enable
dhcp snooping check dhcp-request enable
dhcp snooping check dhcp-rate enable
arp anti-attack check user-bind enable
ip source check user-bind enable
interface GigabitEthernet0/0/1
port link-type hybrid
voice-vlan 4 enable
port hybrid pvid vlan 2
port hybrid tagged vlan 4
port hybrid untagged vlan 2
stp root-protection
stp bpdu-filter enable
stp edged-port enable
trust dscp
stp instance 0 root primary
stp bpdu-protection
3çªç®ã®çµéšã éå¶
NTPãSNMPãAAAãRadiusãå«ã管çéšåãèšå®ãããŸããã
ããã©ã«ãã§ã¯5ã ãã§ãããæ倧16ã®VTYåç·ãã¢ã¯ãã£ãã«ã§ããããšãå€æããŸããã
ãããŠãå®éã«ã¯ãããã€ãã®ç®¡çã®å©äŸ¿æ§ã
user-interface maximum-vty 15
user-interface con 0
authentication-mode aaa
history-command max-size 20
screen-length 40
user-interface vty 0 14
authentication-mode aaa
history-command max-size 20
idle-timeout 30 0
screen-length 40
ãã£ãšæ³šæããããšãéèŠãªã®ã¯äœã§ããïŒ
SSHçµç±ã§ã¢ã¯ã»ã¹ããã«ã¯ãAAAã»ã¯ã·ã§ã³ã®ãŠãŒã¶ãŒãé€ããSSHãŠãŒã¶ãŒãæ£ç¢ºã«è¿œå ããå¿ èŠããããŸãã
RSAããŒã¯ãã§ã«çæãããŠããŸãããã¹ã€ããã®ååãšãã¡ã€ã³ãå€æŽããå Žåã¯ãããŒãå床çæããããšããå§ãããŸãã
ããã©ã«ãã§ã¯ãssh v1ã¯ç¡å¹ã«ãªã£ãŠããŸãããå¿ èŠã«å¿ããŠæå¹ã«ããããšãã§ããŸãïŒãã ããããã¯ãå§ãããŸããïŒã
stelnet server enable
[HUAWEI] aaa
[HUAWEI-aaa] local-user admin123 password irreversible-cipher Huawei@123
[HUAWEI-aaa] local-user admin123 service-type ssh
[HUAWEI-aaa] local-user admin123 privilege level 15
[HUAWEI-aaa] quit
[HUAWEI] ssh user admin123 authentication-type password
ãŸããRadiusãä»ããŠç®¡çè èªèšŒãæ§æããããšãã§ããŸããã
ãã¡ã€ã³default_adminãšåŒã°ããã¹ããŒã ã管çè ã«äœ¿çšãããããšã«æ³šæããŠãã ããïŒ
domain default_admin
authentication-scheme default
accounting-scheme Radius
service-scheme Admin
radius-server Radius
4çªç®ã®çµéšã ããã€ã¹èšŒææžãæå¹ãªãã®ã«çœ®ãæãã
ãããŒããžãç§ãã¡ã¯ãå·¥å Žã§äœæããèªå·±çœ²å蚌ææžãæå¹ãªèšŒææžã«çœ®ãæããããšã«ããŸããïŒçœ²åã«æå¹ãªèšŒææžãããããïŒã
蚌ææžã®ã€ã³ããŒãã¯CLIããã®ã¿å¯èœã§ãã
ãpfxã圢åŒã§ã¯ç§å¯éµã蚌ææžã®äžéšãšããŠãšã¯ã¹ããŒãã§ãããšããäºå®ã«ãããããããéµãšèšŒææžã¯å¥åã§ãªããã°ãªããªãããšã«çŽé¢ããŸããã
ããã«ã蚌ææžã®ãã§ãŒã³ãã€ã³ããŒãããããšããå Žåãããã€ã¹èšŒææžãæåã«èšè¿°ãã次ã«ä»ã®ãã¹ãŠïŒäžéCAãªã©ïŒãèšè¿°ããå¿ èŠããããŸãã
pemãžã®æšæºãšã¯ã¹ããŒãã§ã¯ãCA蚌ææžã¯æåã«ãã¡ã€ã«ã«ç§»åããããã€ã¹èšŒææžã®ã¿ãæåŸã«ãªããŸãã
ã€ã³ããŒããæ©èœãããã«ã¯ãããã€ã¹äžã®èšŒææžãã¡ã€ã«ããã©ãã·ã¥äžã®ã»ãã¥ãªãã£ãã©ã«ããŒã«é 眮ããå¿ èŠããããŸãã ãã®ãã©ã«ããŒã¯ããã©ã«ãã§ã¯æ¬ èœããŠãããããäœæããå¿ èŠããããŸãã
ã¹ãããããšã®ã¢ã«ãŽãªãºã ãã玹ä»ããŸãã
1.å€éšCAã§èšŒææžãçæããŸãã
2.蚌ææžãŸãã¯ãã§ãŒã³ãšç§å¯éµãåå¥ã«ãšã¯ã¹ããŒãããŸãã
3.ããããã§ãŒã³ã®å Žå-蚌ææžãã¡ã€ã«ãã¡ã¢åž³ã§éããæåŸã®ãããã¯ïŒããã€ã¹èšŒææžïŒããã¡ã€ã«ã®å é ã«è»¢éããŠä¿åããŸãã
4.ã¹ã€ããã§ã mkdir flashïŒ/ securityãã©ã«ããŒãäœæããŸã
5.蚌ææžãã¡ã€ã«ãšããŒtftp 192.168.0.1 chain-servercert.pem /security/chain-servercert.pemããã©ã«ããŒã«é 眮ããŸã
ãã®åŸãæ瀺ã«åŸã£ãŠãããªã·ãŒãäœæããŠã€ã³ããŒãããŸãã
ã·ã¹ãã ãã¥ãŒ
[HUAWEI] SSLããªã·ãŒhttp_server
[HUAWEI-ssl-policy-http_server] 蚌ææžããŒãpfx-cert servercert.pfxããŒãã¢rsaããŒãã¡ã€ã«serverkey.pfx auth-codeæå·123456
ïŒSSLããªã·ãŒã®PEM蚌ææžãã§ãŒã³ãããŒãããŸãã
ã·ã¹ãã ãã¥ãŒ
[HUAWEI] SSLããªã·ãŒhttp_server
[HUAWEI-ssl-policy-http_server] 蚌ææžããŒãpem-chain chain-servercert.pemããŒãã¢rsaããŒãã¡ã€ã«chain-servercertkey.pem auth-code cipher 123456
ããªã·ãŒãé©çšããã«ã¯ãhttpsãµãŒããŒãåèµ·åããå¿ èŠããããŸãããåå¥ã«ã¯åèµ·åããŸããã ãããã£ãŠãWebãµãŒãã¹å šäœãåèµ·åããå¿ èŠããããŸãã
HTTPãµãŒããŒã®ç¡å¹å
HTTPãµãŒããŒã®æå¹å
ãã®çµæããšã¯ã¹ããŒãã¯æåããWebã€ã³ã¿ãŒãã§ã€ã¹ã¯ä¿¡é Œã§ãã蚌ææžã䜿çšããŸãã
ãŸãšãããš
ãã®çµæãããã€ãã®å³ãšçµè«ïŒ
- ã¹ã€ããã®CPUè² è·ã¯ãã¢ã€ãã«ç¶æ
ã§ãçŽ20ïŒ
ã§ãããå®æçã«30ïŒ
ã«å¢å ããŸãã ãã©ãã£ãã¯ãžã®åœ±é¿ã¯èªããããŸããã§ããã
5ç§éã®CPU䜿çšçïŒ25ïŒ ïŒ1åïŒ25ïŒ ïŒ5åïŒ24ïŒ
TaskName CPU RuntimeïŒCPU Tick High / Tick LowïŒã¿ã¹ã¯èª¬æ
VIDL 75ïŒ 2 / 187119ffããã©ã¢ã€ãã«
OS 12ïŒ 0 / 55d4a7feãªãã¬ãŒã·ã§ã³ã·ã¹ãã
POE 4ïŒ 0 / 204e4380 POE Power over Ethernet
- æ¥ç¶ãããESXéã§ä»®æ³ãã·ã³ã移è¡ããå Žåãã€ã³ã¿ãŒãã§ã€ã¹ã®è² è·ã¯804 Mbit / sããã³999 Mbit / sã§ããããã±ããæ倱ã¯ãããŸããã§ããã
å ¥åããŒã¯ã¬ãŒã804556024ããã/ç§ãèšé²æéïŒ2016-08-15 15:09:17
åºåããŒã¯ã¬ãŒã999957528ããã/ç§ãèšé²æéïŒ2016-08-12 12:20:09
- é»è©±ã®1ã€ã¯ã1000 Mbit / sã®é床ã§ã100 Mbit / sã®ã¿ã§æ¥ç¶ãå®å šã«æåŠããŸããã äž¡åŽã®èªåèšå®ã ã¹ã€ããã®1mãããã³ãŒããžã®çŽæ¥æ¥ç¶ãã¹ã€ããã®ããŒãã®å€æŽã¯åœ¹ã«ç«ã¡ãŸããã§ããã åæã«ãé»è©±æ©ã¯1Gã®Cisco 2960ã«å®å®ããŠæ¥ç¶ããŸããã ããã¯ã20å°ã®åæ§ã®é»è©±ã®1ã€ã§ãã åé¡ã¯è§£æ±ºãããŠããŸããã
- éåžžã«æ§ãããªWebã€ã³ã¿ãŒãã§ãŒã¹ãæãåºæ¬çãªæ©èœãå©çšå¯èœã§ãã
PS次ã®å·ã§ãäŒãããŸãããã玳士ããšã³ãžãã¢ïŒ